skills/politique-cookies-malik-taiar/SKILL.md
Guide for drafting cookie policies compliant with GDPR and the ePrivacy Directive. Includes CNIL 2020 recommendations, a reference template, and best practices. Use when drafting or revising a cookie policy for a website or application.
npx skillsauth add lawvable/awesome-legal-skills cookie-policy-malik-taiarInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
A cookie policy informs users about cookies and trackers placed on their device. It is distinct from the privacy policy but can be integrated into it. It must comply with CNIL 2020 guidelines.
| Objective | Requirement | |-----------|-------------| | Transparency | Inform about cookies used and their purposes | | Consent | Obtain free, informed, and prior consent | | Control | Allow users to manage their preferences | | Compliance | Comply with GDPR + ePrivacy + CNIL recommendations |
| Template | Description |
|----------|-------------|
| assets/sample_template_politique_cookies.docx | Default template to use if no private template is provided |
| Internal template provided by lawyer | Use if the lawyer has a more suitable private template |
| PDF File to READ (Read tool) | URL to CONSULT (WebFetch tool) | Topic |
|------------------------------|--------------------------------|-------|
| assets/CNIL_lignes_directrices_cookies_et_traceurs.pdf | - | Cookie guidelines |
| assets/CNIL_recommandation_cookies_et_traceurs.pdf | https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies | Cookie recommendations |
| assets/CNIL_faq_cookies_et_traceurs.pdf | https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/FAQ | Cookie FAQ |
| assets/CNIL_evolution_regles_utilisation_cookies.pdf | https://www.cnil.fr/fr/evolution-des-regles-dutilisation-des-cookies-quels-changements-pour-les-internautes | Rules evolution |
| assets/CNIL_transparence.pdf | - | Guide on information and transparency |
| assets/CNIL_principes_rgpd.pdf | - | Fundamental GDPR principles |
| assets/RGPD_texte_officiel.pdf | - | Full text of EU Regulation 2016/679 |
REQUIREMENT: For ANY information regarding cookies, consent, retention periods, exemptions, or best practices:
- READ the PDF files with the Read tool BEFORE responding on a regulatory point
- CONSULT the online URLs with WebFetch to verify the most current information
- CITE the CNIL URL in your response when mentioning a rule or duration
- NEVER invent a duration or rule without verifying it in the sources
| Document | Content | |----------|---------| | COOKIES.md | Cookie categories, banners, CNIL sanctions, retention periods | | BASES_LEGALES_COOKIES.md | Cookie-specific legal bases (consent, exemptions) | | DROITS_PERSONNES.md | Data subject rights | | DUREES_CONSERVATION.md | Retention periods (6 months recommended by CNIL for consent, 13 months max) |
IMPORTANT: Before drafting the policy, collect the information below.
STRICTLY NECESSARY COOKIES (exempt from consent)
ANALYTICS COOKIES
ADVERTISING / MARKETING COOKIES
SOCIAL MEDIA COOKIES
FUNCTIONALITY COOKIES
READ CNIL SOURCE:
assets/CNIL_recommandation_cookies_et_traceurs.pdf+ https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies IMPORTANT: CNIL recommends 6 months for the consent cookie. Use 6 months as default.
| Cookie | CNIL Recommended Duration | Maximum Duration | |--------|---------------------------|------------------| | Consent cookie | 6 months | 13 months | | Analytics cookies | Depending on purpose | 13 months | | Advertising cookies | Depending on purpose | 13 months |
NEVER DRAFT A POLICY FROM SCRATCH. Always start from a given template for drafting, either:
- the default template in
assets/sample_template_politique_cookies.docx;- another internal template provided by the user.
This template is your base reference. You must:
- Faithfully reproduce the template's structure and wording
- Keep the exact template phrasing (they are validated)
- Only replace placeholders with client information
- Do NOT rewrite sentences even if you think you can phrase them better
- Do NOT add sections that are not in the template
The collected information (cookies used, CMP, etc.) is used to fill in the template, not to rewrite it.
1. FIRST ACTION: Confirm the template to use BEFORE any drafting. Ask the user:
"I will draft the cookie policy starting from the provided default template. Do you have an internal template that would be more suitable as a starting point?"
| Option | Action |
|--------|--------|
| Default template | Use assets/sample_template_politique_cookies.docx |
| Internal template | Use the document provided by the lawyer |
2. Consider the user's choice and select the starting template.
MAIN OBJECTIVE: Precisely identify all cookies placed by the site.
1. Ask the lawyer for available information:
"To draft a perfectly tailored cookie policy, please provide:
- The website URL
- The list of cookies used (if known)
- The consent management platform (CMP) used
- Third-party tools integrated (analytics, advertising, social media...)
- Any existing documentation about the site's cookies
You may anonymize this information if necessary for confidentiality reasons.
The more information you provide, the better adapted the policy will be. Otherwise, we will conduct our own research but it will be limited to publicly accessible information."
2. Research on the site (if accessible):
3. Summary before drafting:
SITE: [URL]
CMP USED: [Solution name]
STRICTLY NECESSARY COOKIES: [List]
ANALYTICS COOKIES: [List + providers]
ADVERTISING COOKIES: [List + providers]
SOCIAL MEDIA COOKIES: [List + providers]
FUNCTIONALITY COOKIES: [List]
RETENTION PERIODS: [Compliant with 13 months max?]
KEY LAWYER POINTS: [What must absolutely be included]
Once the summary is ready → Proceed to Draft 1.
ABSOLUTE RULE: The reference template is your validated base.
- START from the template: structure, wording, tone → this is your reference
- ADAPT to the client case: integrate the specific cookies identified
- DO NOT rewrite everything: keep the template wording, only adapt what needs to be
In summary: Template + client cookies = Draft 1. Not a complete rewrite.
Complete the template section by section:
Immediate compliance check: Before presenting Draft 1, verify the cookie compliance checklist (CNIL 2020):
- [ ] Exhaustive list of cookies with name, provider, duration, purpose
- [ ] Distinction between necessary cookies vs cookies requiring consent
- [ ] Information that refusing is as easy as accepting
- [ ] Retention periods ≤ 13 months
- [ ] Clear explanation of how the banner works
- [ ] Instructions for managing cookies via browser
- [ ] Link to CMP to modify preferences
- [ ] Document update date
- [ ] Contact for questions
If Draft 1 is compliant → Proceed to Step 3.
1. Deliver Draft 1 with explanation:
"Here is Draft 1 of the cookie policy.
**What I took into account:**
- [List of identified cookies]
- [CMP used]
- [Retention periods]
**Compliance:** The document complies with CNIL 2020 guidelines."
2. Present the benchmark (systematic):
Research 3-5 cookie policies from companies in the same sector, then present:
"**Benchmark conducted:**
I analyzed the cookie policies of:
- [Company 1] - [what we noted]
- [Company 2] - [what we noted]
- [Company 3] - [what we noted]
**Identified possible improvements:**
- [Improvement 1]: [explanation]
- [Improvement 2]: [explanation]
Would you like to incorporate these elements into the provided Draft?"
3. If the lawyer approves improvements → Produce Draft 2
Final review before definitive delivery:
| Company | Amount | Reason | |---------|--------|--------| | Google | €150M | Refusing cookies more difficult than accepting | | Facebook | €60M | No visible "reject all" button | | Amazon | €35M | Cookies placed without prior consent | | Microsoft | €60M | Cookies placed without consent |
These sanctions illustrate the importance of a compliant cookie policy and a banner respecting the principle that refusing must be as easy as accepting.
| Mistake | Potential Sanction | Solution | |---------|-------------------|----------| | Cookies placed before consent | Fine | Wait for "Accept" click | | No visible "Reject" button | Fine | Button at same level as "Accept" | | Strict cookie wall | Fine | Offer an alternative | | Duration > 13 months | Formal notice | Respect maximum duration | | No cookie list | Non-compliance | Detailed table required | | Dark patterns | Fine | Neutral and clear design | | Incomplete cookie list | Non-compliance | Complete site audit |
TEMPLATE REMINDER: Never draft from scratch. Always start from the reference template and adapt it. DURATION REMINDER: CNIL recommends 6 months for the consent cookie (13 months max). Always verify in CNIL sources before mentioning a duration.
tools
Draft, adapt, and review contracts and clauses aligned with The Chancery Lane Project's methodology for reducing carbon emissions through legal agreements. Use when Claude needs to: (1) Draft new climate-aligned clauses (e.g., net zero commitments, carbon accounting, supply chain decarbonization), (2) Adapt or modify existing contracts to incorporate climate objectives, (3) Review and analyze clauses for alignment with climate goals and decarbonization strategies, (4) Provide guidance on The Chancery Lane Project's house style and drafting methodology for climate-conscious legal work.
development
Matter budgeting and ongoing WIP/variance monitoring. Build phase-based fee estimates at matter setup, run bottom-up budgets by jurisdiction or workstream, calculate contingency, and structure AFA arrangements (fixed fee, capped fee, phased fixed fees). Ongoing monitoring: WIP tracking against budget, proportionality assessment (spend vs progress), variance commentary with root cause analysis, forecast-to-complete, realisation monitoring, write-off analysis. Trigger on: 'build a budget', 'fee estimate', 'what will this cost', 'WIP review', 'budget vs actual', 'how are we tracking against budget', 'we're over budget', 'realisation is poor', 'what's our ETC', 'budget for the German workstream', 'model the financial impact of this scope change', 'draft a fee adjustment', 'write-off analysis', 'how much contingency', 'AFA structure', 'fixed fee estimate', 'budget update', 'forecast to complete'.
tools
Operational billing execution for legal matters. Monthly bill prep and billing instructions, LC invoice review and disbursement treatment, client billing query responses, cashflow modelling (LC payment obligations vs client receipts), and leverage and burn analysis (staffing mix, predicted total cost, margin trajectory). Trigger on: 'prepare the bill', 'billing instruction', 'end of month billing', 'LC invoice', 'local counsel invoice', 'pass through as disbursement', 'client querying the invoice', 'billing dispute', 'cashflow gap', 'when will we get paid', 'LC payment due', 'leverage analysis', 'staffing mix', 'predicted total cost', 'burn rate by grade', 'are we on track', 'what will this matter cost'.
tools
When your bar comes asking "show me how you billed AI-assisted work" — and ABA 512, Florida 24-1, California, New York, and DC all have opinions out — you need an artifact that survives review. billable-time produces it. From your Claude Code session logs, it drafts reviewable time entries plus a printable HTML audit packet with: SHA-256 chain of evidence (source files + matter.yml + active disclosure pack + verifiable artifact self-hash), attorney identity and signature block, a bar-opinion disclosure pack with starter language for five jurisdictions, and content-aware deterministic narratives derived from filename and tool shape — never from prompt text by default. The tool refuses to bill on its own. --strict mode refuses to ship the artifact if any audit invariant fails (broad routes, missing attorney, missing/unverified disclosure). Comes as a Node CLI and a self-contained browser version (no backend; JSONL never leaves the page). 15 invariant tests verify the contract. AGPL-3.0.